Hello David, > What seems strange to me is that the proxy host requires a > certificate just > to tunnel a session to an https backend system... This seems > like quite a > lot of overhead for nothing... well, that is is because it is not just a tunnel. :-) If you want just that, then you could use some kind of port-forward (e. g. via paket-filter rule) BUT that can't inspect http and protect the backend server from (some kinds of) malicious requests. Or rewrite URLs. Regards, Manuel Martin --------------------------------------------------------------------- The official User-To-User support forum of the Apache HTTP Server Project. See <URL:http://httpd.apache.org/userslist.html> for more info. To unsubscribe, e-mail: users-unsubscribe@xxxxxxxxxxxxxxxx " from the digest: users-digest-unsubscribe@xxxxxxxxxxxxxxxx For additional commands, e-mail: users-help@xxxxxxxxxxxxxxxx